Privacy Policy
Last updated: 20 August 2026 · Version 2.0
In short: This Privacy Policy is a separate document from the IDBuddy Terms and Conditions of Service (available at idbuddy.io/terms), which govern organizations’ use of the platform. The policy is published in English, Swedish, Danish and French; in case of discrepancies between language versions, the English version prevails to the extent permitted by applicable law.
Your data, your control
We’re built around memberships, not around selling your attention. Here’s a plain-language summary of what we collect, why, and how you stay in control. The full legal text follows directly after the summary.
The essentials in 30 seconds
We follow the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act. Here’s what that actually means for you as a member or admin.
- We never sell your personal data. Your data is never shared with or sold to ad networks, data brokers or marketing partners. Full stop.
- Your data belongs to you. You can export, correct or delete your data. We respond within 30 days, free of charge.
- We collect only what we need. Name, email, membership status and the interactions the service records, and nothing else. Phone numbers, addresses and similar are not part of a member profile at all.
- Two roles, the same protection. Sometimes we act as controller, sometimes as a processor for your organisation. Protection is identical and we explain the difference clearly.
- Your membership data stays in the EU/EEA. Our database, file storage and scheduled jobs run in an EU region. A short, named list of vendors processes some data elsewhere, and section 11 tells you exactly which and on what legal basis.
- No advertising, no profiling, no ad SDKs. We measure how the site is used and we check sign-ins for automated abuse. Section 17 lists every cookie and every third party your browser contacts.
- Encrypted in transit and at rest. TLS for all traffic, encryption at rest, least-privilege access and logging of administrative access.
- Human contact, and the right to complain. Email info (at) idbuddy.io. You always have the right to lodge a complaint with the Swedish DPA (IMY) if we don’t reach a resolution.
1. Introduction and scope
In short: Who we are, what this policy covers, and which laws we follow.
This policy explains how Byte Buddies AB (corporate ID 559491-4979), hereafter "IDBuddy", "we" or "us", collects, uses, shares and protects personal data when you visit idbuddy.io or use the services hosted at app.idbuddy.io (member app) and admin.idbuddy.io (administrator tool). It also covers ops.idbuddy.io, the internal console our own staff use to operate the platform.
The policy also applies when an organisation that uses IDBuddy adds you as a member. For the membership relationship the organisation is the primary data controller and we act as their data processor. Section 4 develops the two roles further.
We comply with Regulation (EU) 2016/679 ("GDPR"), the Swedish Data Protection Act (2018:218), the Electronic Communications Act (2022:482), and other applicable data-protection legislation.
For organizations using IDBuddy, the processing of their Members’ personal data is further governed by Section 8 of the Terms and Conditions of Service (idbuddy.io/terms) and by the Data Processing Agreement (DPA).
2. Definitions
In short: The GDPR vocabulary used in this policy, gathered in one place.
The following terms have the meanings set out in Article 4 GDPR:
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation or set of operations performed on personal data (collection, storage, alteration, retrieval, erasure, etc.).
- Controller: the entity that, alone or jointly with others, determines the purposes and means of processing.
- Processor: the entity that processes personal data on behalf of a controller.
- Sub-processor: a party engaged by us to process data on our behalf (e.g. cloud host).
- Third country: a country outside the EU/EEA.
- Data subject ("you"): the natural person whose personal data is processed.
- Special categories: sensitive data under Article 9 GDPR (health, ethnic origin, religion, sexual orientation, etc.).
3. Data controller and Data Protection Officer
In short: Byte Buddies AB is responsible; our privacy team answers at info (at) idbuddy.io.
Byte Buddies AB is the data controller for the processing described in this policy where we determine the purposes and means ourselves. Our contact details are set out in the "Contact and complaints" section at the bottom of the policy.
We have not currently appointed a formal Data Protection Officer (DPO) under Article 37 GDPR. Privacy matters, including requests to exercise your rights, are handled by our privacy team and can be addressed to info (at) idbuddy.io. We undertake to appoint a DPO and update this policy accordingly if and when required.
4. Our two roles: controller and processor
In short: For your own account we are the controller; for your membership in an organization we act only on that organization’s instructions.
IDBuddy operates in two distinct data-protection roles depending on context:
- Controller: when you register your own account directly with us, browse our websites, contact our support, or receive marketing directly from us.
- Processor: when you are a member of an organisation that uses IDBuddy as a tool. The organisation then determines the purposes and means; we process the data on their behalf under a data-processing agreement (Article 28 GDPR).
In the processor role we follow the organisation's documented instructions and inform you about the processing through them. Queries about such memberships are addressed primarily to the organisation. We forward requests without undue delay where required, and we assist the organisation to the extent Article 28(3)(e) demands.
5. What personal data we process
In short: A member profile is a name, an email address and a picture. Everything else is a record of something you did.
We process only the personal data necessary for the relevant purpose and apply the data-minimisation principle under Article 5(1)(c) GDPR. Depending on your role, the following categories may apply.
5.1 Account data
Your first and last name, your email address and, if you upload one, a profile picture. Your password is held by our authentication provider as a salted hash and is never visible to us. If you sign in with Google instead of a password, we also store the identity details Google returns to us about your account, such as the identifier Google uses for you and whether Google has verified your address.
There is no phone number, postal address, date of birth or free-text note on a member profile. Those fields do not exist in the platform, and an organisation cannot add them.
5.2 Membership data
Which organisations you are a member of, the display name that organisation knows you by, your role in that organisation and the date you joined. Your digital membership card and the QR code it shows. Where an organisation charges a membership fee, the record it keeps against your membership: the amount, the currency, the period it covers and whether the payment succeeded.
5.3 Interaction data
What the service records when you use it. Each time your QR code is scanned we record who scanned it, for which organisation, when, whether the code was valid, what the scan was for and its outcome. So that the admin doing the scan can see who is in front of them, we also store a copy of your name as it stood at that moment. Your stamp cards and each individual stamp. Offers you have claimed. Newsletters an organisation has queued and sent to you.
5.4 Data about events and places
If you administer an organisation, the events you create carry a venue name, a street address and map coordinates. Where you type an address, we look it up through a third-party geocoding service so the map can show the right place. Section 11 names the service.
5.5 Data you send us outside the product
If you request a quote through the form at idbuddy.io/get-started, that form collects your name, your position, your email address, your phone number, your organisation's address and its invoicing details, including a bank giro or bank account number where you provide one. Today that form opens your own email client and sends the details to info (at) idbuddy.io as an ordinary email, so it reaches us as mail rather than through the platform. The same applies to anything you write to info (at) idbuddy.io or contact (at) idbuddy.io: we keep the correspondence.
We do not operate a chat service, we do not record calls, and we do not have a helpdesk system.
5.6 Technical data
We do not store IP addresses, device identifiers or browser fingerprints in our own database. Our hosting, database and bot-protection providers do process technical data of this kind in order to serve the site, keep it available and block automated abuse; section 11 names them and section 17 explains what runs in your browser.
6. Where your data is stored, and why
In short: One EU database holds almost everything. This section names every other place a piece of your data goes, and what it is doing there.
Article 13(1) requires us to tell you who receives your data. We think you should also be able to see where it physically sits, so here is the map.
- Our database, in an EU region at Supabase. This is the system of record: accounts, memberships, membership cards, stamp cards, offers, offer claims, events, invitations, scan history and the queue of newsletters to be sent. It is there because the service cannot function without it, and it is in the EU because that is where our members are.
- File storage, in the same EU region at Supabase. Profile pictures, organisation logos and the images organisations upload for their member pages, events and offers. Stored so the apps can display them.
- Our email delivery provider, Resend. Every message the platform sends passes through it: sign-in links, password resets, invitations and organisation newsletters. It receives the recipient's address, the subject and the message body, and it keeps delivery logs. Resend is a United States company; see section 12.
- Our application host, Vercel. The four IDBuddy websites run there. Vercel processes the technical data that serving a web request involves, and it also provides the usage measurement and the sign-in bot protection described in section 17. Vercel is a United States company; see section 12.
- Google, only if you choose it. Pressing "Continue with Google" sends you to Google to sign in, and Google tells us your email address and basic account details in return. If you use a password instead, Google receives nothing.
- OpenStreetMap, for maps in the administrator tool. When an admin types an event address or views the events map, the address text and the map area are requested from OpenStreetMap servers. Members are not affected; this only happens in the admin tool.
- Our own mailbox. Correspondence with info (at) idbuddy.io and contact (at) idbuddy.io, and quote requests submitted through the get-started form, sit in ordinary business email rather than in the database above.
- Encrypted backups of the database, held by Supabase in the same region and overwritten on a rolling cycle.
We do not copy your personal data to any analytics warehouse, customer-data platform, advertising system or data broker, and we do not use it to train machine-learning models.
7. Where we get the data
In short: Your data comes from you, from your organization, and from the way you use the service.
Article 14(2)(f) GDPR requires us to be transparent about the sources of personal data. We collect data from the following sources:
- Directly from you: when you register an account, update your profile, change settings, or contact us.
- From organisations that use IDBuddy: when an organisation invites you to join it. We process this data in the processor role. An invitation records your email address before you have any account with us, and section 10 says how long we keep it.
- From your identity provider: if you sign in with Google, the account details Google returns to us.
- Automatically through use: your interaction history is generated as you use the service, and our providers generate technical data as described in section 5.6.
8. Purposes and legal basis
In short: Every purpose has a named legal basis; marketing from us always requires your consent.
We process your data for the following purposes, on the legal bases set out below per Article 6(1) GDPR. Where processing rests on legitimate interest (Article 6(1)(f)) we always perform a documented balancing test demonstrating that our legitimate interest is not overridden by your interests, rights and freedoms, and you can object at any time (see section 16).
- Delivering and maintaining the service (account, sign-in, membership card, check-ins): contract, Art. 6(1)(b).
- Sending system notices related to your account (sign-in links, password resets, change notifications, security alerts): contract, Art. 6(1)(b).
- Sending newsletters and marketing from IDBuddy: consent, Art. 6(1)(a). You can withdraw your consent at any time, from your communication settings in the app or through the unsubscribe link in every marketing email, and we act on it immediately.
- Sending newsletters and offers from your organisation: the organisation decides the legal basis for its own mailings, and we act on its instructions as processor. In either case you can stop them, from your communication settings or from the unsubscribe link in the message.
- Handling support and service requests: contract or legitimate interest, Art. 6(1)(b) and (f).
- Preventing fraud, abuse and security incidents, including automated checks on sign-in and account creation: legitimate interest, Art. 6(1)(f). Our interest is to protect you and the service. Section 18 explains this check and how to have a decision reviewed.
- Measuring how our websites are used so we can improve them: legitimate interest, Art. 6(1)(f), on aggregated measurement only. Section 17 explains what is collected and how to opt out.
- Improving and developing the service through aggregate statistics and troubleshooting: legitimate interest, Art. 6(1)(f), with pseudonymisation where possible.
- Meeting legal obligations (bookkeeping, tax, responding to authorities): legal obligation, Art. 6(1)(c). Swedish Bookkeeping Act (1999:1078) and others.
- Meeting legal claims and asserting or defending our rights: legitimate interest, Art. 6(1)(f).
- Marketing IDBuddy to admins at existing organisations (B2B): legitimate interest, Art. 6(1)(f), with a right to object.
9. Special categories and children's data
In short: We never ask for sensitive data, and we do not read what organisations write. If your membership list is sensitive by its nature, section 9.2 is written for you.
9.1 Special categories under Article 9
We do not ask for, and the platform has no field for, any of the special categories listed in Article 9 GDPR: health, racial or ethnic origin, political opinions, religious or philosophical belief, trade-union membership, genetic or biometric data, sex life or sexual orientation. A member profile holds a name, an email address and a picture.
Our Terms prohibit organisations from uploading or processing special-category data unless a valid exception applies (Section 10.1). You should know exactly how far that goes, because the honest answer matters more than a reassuring one:
- We do not inspect the content organisations write into their own fields. There is no scanning, no classifier and no detection, so we cannot promise to find such data on our own.
- We act on reports. If you tell us, or if we otherwise become aware, that an organisation is processing special-category data in breach of our Terms, we investigate, require the organisation to remove it, and notify the organisation.
- We can enforce it. We are able to switch off individual capabilities for a single organisation, including its ability to send messages, and to suspend or terminate access entirely. We do this where an organisation will not correct a breach.
- The organisation remains the controller. Where an organisation puts special-category data into IDBuddy, that organisation, not IDBuddy, has to have an Article 9 condition for it.
9.2 When membership itself is sensitive
Some memberships reveal a special category simply by existing. Belonging to a faith community, a trade union, a political association or an LGBTQ organisation reveals religion, union membership, political opinion or sexual orientation, and the Court of Justice has confirmed that data which reveals such information indirectly is still caught by Article 9 (Case C-184/20).
If you are an organisation of that kind, treat your whole membership list as Article 9 data, identify your condition under Article 9(2), which for a non-profit association is usually Article 9(2)(d), and keep your list inside the organisation. We support that by not exposing member lists to other organisations and by letting you turn off your public discoverability.
9.3 Children
The Service is not directed at children under 13, and we do not market to children. Workspace administrators must be at least 18 years old (see our Terms).
Where consent is the legal basis, the age at which a child can consent for themselves differs by country: 13 years in Sweden under Chapter 2, Section 4 of the Swedish Data Protection Act (2018:218), and between 13 and 16 years elsewhere in the EU/EEA under Article 8(1) GDPR. Below that age, the consent has to be given or authorised by the holder of parental responsibility.
Where an organisation adds members who are minors, the organisation, as data controller, is responsible for complying with Article 8 GDPR and the age threshold that applies to it, including obtaining parental consent where required. IDBuddy does not collect a date of birth and therefore cannot assess anyone's age; an organisation that enrols minors has to handle that outside the platform. If we become aware that we have collected personal data from a child without a valid legal basis, we will delete it as soon as reasonably practicable.
10. How long we keep your data
In short: A period for every category, not a vague promise. When the period ends we delete or anonymise.
We keep personal data only as long as necessary for the purpose for which it was collected, or as required by law. The periods below apply to our own processing as controller. Where we act as processor, your organisation as controller decides how long its membership data is kept, and it can instruct us to delete sooner.
- Account data: for as long as your account exists. If you have not signed in for 24 months we contact you, and if you do not return we delete or anonymise the account.
- Membership data: for as long as the membership lasts, and 12 months afterwards, unless your organisation instructs us otherwise.
- Membership fee records an organisation keeps against you: for the period that organisation's own accounting law requires. For a Swedish organisation that is seven years under Chapter 7, Section 2 of the Bookkeeping Act (1999:1078).
- Check-in, stamp and offer history: 24 months from the interaction, or 12 months after the membership ends, whichever comes first.
- Newsletter dispatch records: 12 months from sending.
- Evidence that you gave marketing consent: for as long as the consent lasts and 24 months afterwards, so that we can show it existed.
- A record that you objected to marketing or unsubscribed: kept indefinitely. This is the only way we can keep honouring it, and deleting it would let the objection be undone by a later import.
- Invitations that have been accepted, revoked or have expired: 30 days, then deleted.
- Correspondence with our support: 24 months after the matter is closed.
- Our own bookkeeping records: seven years under the Bookkeeping Act (1999:1078).
- Security logs, including sign-in and administrative access: 12 months, or longer while an incident is under investigation.
- Operational and troubleshooting logs: 30 days.
- Encrypted backups: overwritten on a rolling cycle of no more than 35 days.
When a period ends we delete the data or anonymise it so that it can no longer be linked to you.
11. Recipients and sub-processors
In short: Six named vendors, what each one does, and where it sits. Never advertisers or data brokers.
We share data with the vendors needed to operate the service. All are bound by data-processing agreements under Article 28 GDPR and by confidentiality and security obligations. We only engage providers that offer sufficient guarantees of GDPR compliance. The current list is:
- Supabase Inc. (United States), with our project provisioned in an EU region. Database, authentication, file storage and scheduled jobs. This is where your account, membership and interaction data lives.
- Vercel Inc. (United States). Hosting for idbuddy.io, app.idbuddy.io, admin.idbuddy.io and ops.idbuddy.io, plus the aggregated usage measurement and the sign-in bot protection described in section 17.
- Resend, Inc. (United States). Delivery of every email the platform sends. Message content and recipient addresses pass through it and its delivery logs and message metadata are held in the United States.
- Google Ireland Limited, with Google LLC (United States) as its sub-processor. Only where you choose "Continue with Google" to sign in.
- OpenStreetMap Foundation (United Kingdom). Address lookup and map tiles in the administrator tool. Marker images for those maps are served from a public code distribution network operated by Cloudflare, Inc. (United States).
- A hosted business email service for correspondence with info (at) idbuddy.io and contact (at) idbuddy.io.
We do not use advertising networks, data brokers, customer-data platforms or third-party analytics products beyond the aggregated measurement named above.
Before we engage a new sub-processor we perform a risk assessment, ensure a valid legal basis for any third-country transfer, and inform our customers in good time so they can object. Organisational customers can find the authoritative list, and the mechanism for objecting to a change, in the DPA; a copy is available free of charge from info (at) idbuddy.io.
12. Transfers outside the EU/EEA
In short: Your membership data sits in the EU. Some named vendors are US companies, and each transfer has a legal basis we can show you.
Your account, membership and interaction data is stored in an EU region, and our own staff access it from Sweden. Several of the vendors in section 11 are established outside the EU/EEA, so some processing reaches a third country. Where it does, it happens only on one of the following grounds under Articles 44 to 49 GDPR:
- Adequacy decision (Article 45). The United Kingdom is covered by an adequacy decision, which is the basis for the OpenStreetMap processing in section 11.
- European Commission Standard Contractual Clauses (Article 46), supplemented with technical and organisational safeguards: encryption in transit and at rest, access controls and transparency undertakings. This is the basis for Supabase, Vercel, Resend and Cloudflare.
- The EU-US Data Privacy Framework, where the vendor is certified under it and the processing falls within its scope.
We carry out a Transfer Impact Assessment before initiating a new third-country transfer to ensure the level of protection is essentially equivalent to that of the EU. You can request current information on transfers via info (at) idbuddy.io.
13. Disclosure to public authorities
In short: Authorities receive data only when the law compels it, and we review every request first.
We disclose personal data to Swedish or foreign public authorities only when required by law, a court order, or a binding order from a competent authority.
Every request is formally and legally reviewed before any disclosure, and we keep a record of the requests we receive and how we handled them. Where the law permits, we notify the data subject. We challenge requests that fail to meet legal requirements, are disproportionate, or lack a legal basis.
14. Your GDPR rights
In short: Access, correct, delete, export, object. All free of charge, answered within 30 days.
You have the following rights under Articles 15–22 GDPR. We handle every request free of charge and respond within 30 days (extendable by two months in complex cases, in which case we will tell you the reason).
- Right to be informed (Art. 13–14): to know what data we process and why. This policy fulfils the bulk of that.
- Right of access (Art. 15): a copy of the personal data we hold about you, including your interaction history.
- Right to rectification (Art. 16): correct inaccurate or complete incomplete data.
- Right to erasure (Art. 17): ask us to delete your data where no legal basis remains. Some exceptions apply, such as our bookkeeping obligations and the record of a marketing objection described in section 10.
- Right to restriction (Art. 18): pause processing while a complaint is investigated or accuracy is contested.
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format and transfer it to another controller.
- Right to object (Art. 21): to processing based on legitimate interest or direct marketing.
- Right not to be subject to fully automated decisions (Art. 22) producing legal or similarly significant effects. See section 18.
- Right to withdraw consent (Art. 7.3): withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Where we hold the data as processor for an organisation, we forward your request to that organisation and help it respond.
15. How to exercise your rights
In short: Email us, use the privacy settings in the app, or write to us by post.
Requests to exercise any of the rights in section 14 are made most easily via:
- Email: info (at) idbuddy.io, stating clearly which right you are invoking.
- Logged in to the service: your account settings offer self-service for exporting your data, managing your communication preferences and deleting your account.
- Postal mail: Byte Buddies AB, Privacy Team, Malmö, Sweden.
To protect you from identity theft we may need to verify your identity (e.g. by an existing sign-in or other reasonable check). If we cannot identify you we may decline to act on the request under Article 11(2).
If you are a member of an organisation and your request concerns that membership, we may need to forward the request to the organisation that is the data controller.
16. Direct marketing and right to object
In short: One objection stops all direct marketing from us, permanently.
You have an unconditional right under Article 21(2) GDPR to object to the processing of your personal data for direct-marketing purposes. The objection is honoured without delay and without you needing to state a reason.
We keep a record of everyone who has objected to marketing. It is checked before a message is queued and again before it is sent, it applies across our systems, and it is never lifted automatically, not by a later import and not by rejoining an organisation.
- Marketing from IDBuddy: use the unsubscribe link in any marketing email, change your communication settings in the app, or email info (at) idbuddy.io.
- Mailings from an organisation you are a member of: use the unsubscribe link in the message or your per-organisation communication settings in the app. You can also contact the organisation directly.
17. Cookies, local storage and similar technologies
In short: No advertising or cross-site tracking. Here is every cookie, every browser storage entry and every third party your browser is asked to contact.
Chapter 9, Section 28 of the Swedish Electronic Communications Act (2022:482) covers anything stored in or read from your device, not only cookies, so this section lists both.
17.1 Strictly necessary
These are set without consent because the service cannot work without them.
- idbuddy.locale: a first-party cookie, and a matching entry in your browser's local storage, that remembers your language for 12 months. It is scoped to idbuddy.io so your choice carries across our subdomains.
- The Supabase Auth session cookie, named after our project and sometimes split across two entries. It keeps you signed in and is currently set for a long-lived session, up to 400 days; signing out removes it.
- pending_invite_id and pending_invite_link_id: first-party cookies that live for 5 to 10 minutes and carry the invitation you clicked through the sign-in round trip, so you land in the right organisation.
- idbuddy_admin_selected_company: a local-storage entry in the administrator tool that remembers which organisation you last had open. It is written when you first open the tool and stays until you clear your browser storage.
- Cookies beginning KP_, set by our bot-protection provider when a sign-in is checked. See section 18.
17.2 Usage measurement
We measure how our websites are used with Vercel Web Analytics. It reports which page was viewed and basic technical details of the request to Vercel, and it does not set a cookie or build a profile of you. We use it in aggregate to see which pages people need and where they get stuck.
Because the page address is part of what is reported, and because addresses inside the member app can contain an organisation identifier, we treat this as processing that needs a legal basis, and we rely on legitimate interest rather than treating it as strictly necessary. You can turn it off from your privacy settings in the app, and we honour that choice.
17.3 What we do not do
We do not set advertising, profiling or cross-site tracking cookies. We do not embed advertising SDKs, social media pixels, session recorders or heatmap tools. We do not load web fonts from a third party. Every font is served from our own domain.
You can clear cookies and site data at any time via your browser settings; you may need to sign in again afterwards.
18. Automated decisions and profiling
In short: One automated check runs on sign-in, to keep bots out. If it blocks you, a human will look at it.
We do not profile you, score you, rank you or segment you as an individual on the basis of your behaviour, and we do not sell or share any such data. There is no advertising or recommendation model in the product.
There is one automated check. When you sign in or create an account, our bot-protection provider assesses the request, looking at the browser and device characteristics and the pattern of the request rather than at who you are, and returns a verdict on whether it came from an automated client. If the verdict is that it did, the account creation is refused. This is the only automated decision in the service that can affect your access to it.
If you are refused, that is not the end of it. Write to info (at) idbuddy.io and a person will review the decision and, where the refusal was wrong, complete the registration for you. That is your right under Article 22(3), and we would rather hear about a false positive than lose you to one.
Aggregate statistics and segmentation are used only to:
- Help your organisation understand its own membership, for example how many members it has and how many stamps have been issued.
- Troubleshoot and monitor the performance of the service.
- Improve our product.
19. Anonymisation and aggregate data
In short: Data that can no longer identify you may be kept for long-term statistics.
We anonymise personal data when it is no longer needed for identifying purposes. Properly anonymised data is outside the scope of the GDPR (Recital 26) and may therefore be used for long-term statistics and product development without being linked back to you.
Where full anonymisation is not possible we reduce what identifies you: for example, when the retention period for your check-in history ends, the record of the interaction can be kept for statistics with your name and your account reference removed, so that neither we nor the organisation can trace it back to you.
20. Security and data breaches
In short: Encryption, least-privilege access and access logging; if a breach puts you at risk, we notify you and IMY.
We apply appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, costs of implementation, the nature and scope of the processing and the risk to your rights and freedoms. Examples:
- TLS 1.2 or higher for all traffic in transit, and encryption at rest for the database, file storage and backups.
- Row-level security in the database, so that an organisation's data is reachable only by that organisation, enforced by the database itself rather than by application code.
- Every write to the platform goes through a checked server-side function rather than a direct database write from the browser.
- Access by our own staff is governed by the principle of least privilege, protected by two-factor authentication, and logged.
- Regular security reviews, and penetration testing of the platform.
- Encrypted, geographically separated backups.
- Staff are trained in data protection and bound by confidentiality.
In a personal data breach likely to result in a risk to your rights and freedoms, we will notify IMY within 72 hours per Article 33 GDPR. Where the risk is high under Article 34, we will notify you directly by email and via a clear notice in the app, describing the scope, likely consequences and the measures we have taken or recommend you take.
21. Changes to this policy
In short: Material changes are announced at least 30 days in advance.
We may update this policy to reflect changes in law, new services, or improved practice. The date at the top reflects the most recent revision.
For material changes affecting your rights or expanding our processing, we will notify you by email and via a clear notice in the app at least 30 days before the change takes effect. For non-material changes (language edits, typo fixes) the updated version applies from the publication date.
Earlier versions of the policy can be requested at info (at) idbuddy.io.
22. Complaints to the supervisory authority
In short: Not satisfied? You can always complain to IMY or your local supervisory authority.
We appreciate hearing from you directly if something feels wrong. Write to info (at) idbuddy.io and we will resolve it promptly. You always have the right under Article 77 GDPR to lodge a complaint with the supervisory authority, in parallel or without contacting us first.
In Sweden this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). If you live or work in another EU/EEA country you may also contact the supervisory authority there.
- Postal address: Box 8114, 104 20 Stockholm, Sweden
- Email: imy (at) imy.se
- Website: imy.se
Contact and complaints
Questions about how we handle your personal data, or want to exercise any of your rights? Get in touch. We respond within 30 days. If you believe we have processed your data in breach of the GDPR, you also have the right to lodge a complaint with the supervisory authority.
Data controller
Byte Buddies AB
Corp. ID 559491-4979
Malmö, Sweden
Supervisory authority
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
imy (at) imy.se · imy.se